Aias00 opened a new issue, #6468:
URL: https://github.com/apache/shenyu/issues/6468

   ### Current Behavior
   
   The JWT plugin can throw `ArrayIndexOutOfBoundsException` when the incoming 
`Authorization` header contains the `Bearer` marker but does not contain a 
token in the expected second segment.
   
   In current `origin/master`, `JwtPlugin.compatible()` does:
   
   ```java
   return isAuth2(finalAuthorization) ? finalAuthorization.split(" ")[1] : 
finalAuthorization;
   ```
   
   and `isAuth2()` only checks:
   
   ```java
   return authorization.contains(AUTH2_TOKEN);
   ```
   
   So values such as `Authorization: Bearer` or other malformed strings 
containing `Bearer` can pass `isAuth2()` and then fail at `split(" ")[1]`.
   
   ### Expected Behavior
   
   Malformed JWT authorization headers should be rejected as an invalid token 
and return the normal unauthorized/error response instead of throwing an 
uncaught runtime exception.
   
   ### Steps to Reproduce
   
   1. Enable the JWT plugin for a route.
   2. Send a request with a malformed header, for example:
   
   ```http
   Authorization: Bearer
   ```
   
   3. The plugin attempts to access index `1` after splitting the header by a 
space.
   
   ### Code Location
   
   - 
`shenyu-plugin/shenyu-plugin-security/shenyu-plugin-jwt/src/main/java/org/apache/shenyu/plugin/jwt/JwtPlugin.java`
   - `compatible()`, lines around 100-113 in current `origin/master`
   
   ### Notes
   
   If PR #6450 is intended to fix this path, this issue can be linked to that 
PR.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to